MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dcb76c24685fd31d5ac64851fe8e3b41a4462d882eda656fbc7faac89a763f8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 11


Intelligence 11 IOCs YARA 10 File information Comments

SHA256 hash: dcb76c24685fd31d5ac64851fe8e3b41a4462d882eda656fbc7faac89a763f8f
SHA3-384 hash: ad185a2b1b89ac42699a3b94b6f23f64d428e590edbd70bee204ae8a3495e25d4f4585a0434898d796685513bdfabd83
SHA1 hash: 80f48bf48374f354417265fe53fcc35e251b25a4
MD5 hash: 8ccde13d5ca60e39bbd24fe34cfb7743
humanhash: ten-mobile-river-yellow
File name:wdll.dll
Download: download sample
File size:1'273'488 bytes
First seen:2025-12-09 14:52:27 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash d15363fe7543b1a474001ec498c42e1c
ssdeep 24576:HD5JU5xVmm+6uzofz/jNCcF0kJLrpVIiEsXwteQelECCAYuv:dJexInRofz/jt0opVcsgteQtNAFv
TLSH T1D645E062BA42C0B2E49A0030A6B9DBBB2D3D35B9072490D3F7D5497969301D3B739F5B
TrID 32.2% (.EXE) Win64 Executable (generic) (10522/11/4)
20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
15.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
13.7% (.EXE) Win32 Executable (generic) (4504/4/1)
6.2% (.EXE) OS/2 Executable (generic) (2029/13)
Magika pebin
Reporter smica83
Tags:dll signed Xiamen-Aoyuhui-Ao-IoT

Code Signing Certificate

Organisation:厦门市奥裕晖奥物联网科技研究院有限公司
Issuer:Certum Extended Validation Code Signing 2021 CA
Algorithm:sha256WithRSAEncryption
Valid from:2025-11-28T12:27:09Z
Valid to:2026-11-28T12:27:08Z
Serial number: 2de40589c464f0b18a796872f53a4bc8
Intelligence: 5 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 6a6e10d3c702dd3b598774f125370cb1e87642a51c842bef6e2634440e721e0d
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.2%
Tags:
injection emotet obfusc smtp
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context base64 crypto microsoft_visual_cc packed signed
Verdict:
Malicious
File Type:
dll x32
First seen:
2025-12-09T08:28:00Z UTC
Last seen:
2025-12-10T02:35:00Z UTC
Hits:
~100
Detections:
Trojan.Win32.Inject.sb Trojan.Win32.Agent.sb Trojan.Win32.Agent.xcbiqv
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
AI detected suspicious PE digital signature
Allocates memory in foreign processes
Creates a thread in another existing process (thread injection)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Opens the same file many times (likely Sandbox evasion)
Sigma detected: Potential WinAPI Calls Via CommandLine
Sigma detected: rundll32 run dll from internet
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1829574 Sample: wdll.dll Startdate: 09/12/2025 Architecture: WINDOWS Score: 100 29 ww7.win1c1.com 2->29 31 t.zumopc.com 2->31 35 Multi AV Scanner detection for submitted file 2->35 37 Sigma detected: rundll32 run dll from internet 2->37 39 AI detected suspicious PE digital signature 2->39 41 2 other signatures 2->41 8 loaddll32.exe 1 2->8         started        signatures3 process4 process5 10 rundll32.exe 8->10         started        13 cmd.exe 1 8->13         started        15 rundll32.exe 8->15         started        17 30 other processes 8->17 signatures6 51 Writes to foreign memory regions 10->51 53 Allocates memory in foreign processes 10->53 55 Creates a thread in another existing process (thread injection) 10->55 57 Injects a PE file into a foreign processes 10->57 19 svchost.exe 245 10->19 injected 23 rundll32.exe 13->23         started        25 WerFault.exe 22 16 15->25         started        27 WerFault.exe 17->27         started        process7 dnsIp8 33 ww7.win1c1.com 45.119.4.217, 49693, 49694, 49698 SUPERCLOUDSLIMITED-AS-APSUPERCLOUDSLIMITEDHK Hong Kong 19->33 43 Tries to detect sandboxes and other dynamic analysis tools (window names) 19->43 45 Opens the same file many times (likely Sandbox evasion) 19->45 47 Unusual module load detection (module proxying) 19->47 49 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 19->49 signatures9
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-09 13:22:33 UTC
File Type:
PE (Dll)
Extracted files:
1
AV detection:
13 of 38 (34.21%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
System Location Discovery: System Language Discovery
Unpacked files
SH256 hash:
dcb76c24685fd31d5ac64851fe8e3b41a4462d882eda656fbc7faac89a763f8f
MD5 hash:
8ccde13d5ca60e39bbd24fe34cfb7743
SHA1 hash:
80f48bf48374f354417265fe53fcc35e251b25a4
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:HeavensGate
Author:kevoreilly
Description:Heaven's Gate: Switch from 32-bit to 64-mode
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:TH_Generic_MassHunt_Win_Malware_2025_CYFARE
Author:CYFARE
Description:Generic Windows malware mass-hunt rule - 2025
Reference:https://cyfare.net/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments